Exact Sciences

Senior Cybersecurity Risk Management Analyst

Exact Sciences$101K — $172K *
Healthcare
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree in a related field; or Associate Degree with 2 years of relevant experience; or High School Diploma/GED with 4 years of relevant experience.
  • 6+ years of experience in cybersecurity or IT governance, risk, compliance, or operations.
  • 1+ years of cybersecurity risk management experience.
  • Experience with security risk management and compliance frameworks (e.g., NIST, ISO, HIPAA).
  • Strong communication skills tailored to audience needs.

Responsibilities

  • Support risk management activities by assisting with all stages of the risk management lifecycle.
  • Maintain and contribute to the global cybersecurity risk register.
  • Assist in cybersecurity risk appetite discussions to ensure relevance to business operations.
  • Aggregate and evaluate cybersecurity risks for leadership reporting.
  • Facilitate risk identification and analysis discussions with trust-building methods.
  • Proactively analyze emerging risks and threats against the existing risk posture.
  • Deliver risk management training and support stakeholder inquiries.

Benefits

  • Paid time off for vacation, holidays, volunteering, and personal time.
  • Paid leave for parents and caregivers.
  • Retirement savings plan and wellness support.
  • Comprehensive health benefits including medical, prescription drug, dental, and vision coverage.
Full Job Description
Position Overview

At Exact Sciences, we are cancer fighters. We are united by our mission to change lives by providing earlier, smarter answers. Through advances in cancer detection and treatment guidance, we will help eradicate the disease and the suffering it causes. Exact Sciences' Cybersecurity organization supports this mission by defending the millions of digital patient, practitioner, and employee lives within our environments. Defending today and securing tomorrow is no small feat. To help achieve this, the team is in search of a cybersecurity risk management subject matter expert to join our collaborative team comprised of passionate experts.

The Senior Cybersecurity Risk Management Analyst, reporting to the Director of Cybersecurity Strategy & GRC, is responsible for supporting and advancing the organization's cybersecurity risk management program. This role requires a deep understanding of security and IT risk principles, processes, and practices, combined with the ability to integrate security into business operations. The position demands both technical expertise and strong cultural awareness to effectively identify, assess, monitor, and report cybersecurity risks across the enterprise.

This role requires regular onsite work in Madison, WI.

Essential Duties

Include, but are not limited to, the following:
  • Support cybersecurity risk management activities by assisting with defined stages of the risk management lifecycle and completing assigned analyses under established methodologies.
  • Maintain and contribute to the global cybersecurity risk register.
  • Assist management by providing input to cybersecurity risk appetite discussions and support implementation and enforcement efforts-making it relevant to the business on a day-to-day basis.
  • Aggregate and evaluate cybersecurity risks to support management and leadership reporting, ensuring accuracy and consistency for various global audiences.
  • Build trust and effectively facilitate risk identification/analysis/treatment discussions.
  • Proactively obtain information on emerging risks and threats and effectively analyze against the risk posture.
  • Support the delivery of risk management education by preparing materials, reinforcing frameworks, and responding to stakeholder questions.
  • Work with leadership to support the prioritization of initiatives aligned with strategic goals.
  • Act as a resource providing training, guidance, and mentoring to less experienced staff.
  • Collaborate with stakeholders to remediate visibility and capability gaps and breakdown roadblocks standing in the way of a robust security posture.
  • Enable the maturation of the security program functions within the cybersecurity team and with key business partners.
  • Research and summarize industry insights and best practices, along with interpreting impact of requirements from governing authorities.
  • Uphold company mission and values through accountability, innovation, integrity, quality, and teamwork.
  • Support and comply with the company's Quality Management System policies and procedures.
  • Maintain regular and reliable attendance.
  • Ability to act with an inclusion mindset and model these behaviors for the organization.
  • Ability to travel 10% of working time away from work location, may include overnight/weekend travel.


Minimum Qualifications
  • Bachelor's Degree in field related to essential duties; or Associate Degree and 2 years of relevant experience; or High School Diploma or General Education Degree (GED) and 4 years of relevant experience.
  • 6+ years of professional experience in a cybersecurity or IT governance, risk, compliance, or operations role.
  • 1+ years of experience with cybersecurity risk management.
  • Demonstrated experience with security risk management and compliance frameworks (e.g., NIST, ISO, HIPAA).
  • Experience evaluating risk rating methodologies to appropriately convey the enterprise cybersecurity posture.
  • Demonstrable experience conducting risk assessments and facilitating executive level risk discussions.
  • Experience managing cybersecurity risks through the risk management lifecycle, in a globally regulated enterprise a plus.
  • Solid grasp of security governance, risk, and compliance concepts.
  • Technically proficient in performing assigned duties at a high-level of independence under minimal supervision while working within a team environment.
  • Demonstrated leadership skills, ability to influence outcomes in a complex environment, where you may/may not have formal reporting responsibility.
  • Excellent communication skills, appropriately adapting based on audience needs, through all mediums-verbal, written, presentation, and listening.
  • Able to be agile and work with ambiguity.
  • Proficient+ in Microsoft Office programs, such as PowerPoint, Excel, Outlook, and Word.
  • Demonstrated ability to perform the essential duties of the position with or without accommodation.
  • Authorization to work in the United States without sponsorship.


Preferred Qualifications
  • Relevant certification(s) in the field of cybersecurity, risk, audit, or program/project management.
  • Experience contributing to the build and continuous improvement of the risk management environment, in a globally regulated enterprise strongly preferred.
  • Experience with enterprise GRC management platforms (e.g., ServiceNow, OneTrust); implementation experience a plus.
  • Advanced proficiency in program/project management to drive program build efficiently and effectively.
  • Experience in healthcare or biotech industries.
#LI-GV1

Salary Range:
$101,000.00 - $172,000.00

The annual base salary shown is for this position located in US - WI - Madison on a full-time basis. In addition, this position is bonus eligible.

Exact Sciences is proud to offer an employee experience that includes paid time off (including days for vacation, holidays, volunteering, and personal time), paid leave for parents and caregivers, a retirement savings plan, wellness support, and health benefits including medical, prescription drug, dental, and vision coverage. Learn more about our benefits.

Our success relies on the experiences and perspectives of a diverse team, and Exact Sciences fosters a culture where all employees can develop personally and professionally with a sense of respect and belonging. If you require an accommodation, please contact us here.

Not ready to apply? Join our Talent Community to stay updated on the latest news and opportunities at Exact Sciences.

About Exact Sciences

Exact Sciences is a biotechnology company that develops and commercializes diagnostic tests for the early detection and prevention of cancer. The company's flagship product is Cologuard, a non-invasive stool-based DNA test for colorectal cancer screening. Exact Sciences was founded in 1995 and is headquartered in Madison, Wisconsin.
Learn more about Exact Sciences
Size
6,420 employees
Market Cap
$9.2 billion
Industry
Net Income
-$848.5 million
Founded
1995
5 Year Trend
+77.8%
Revenue
$1.4 billion
NASDAQ

Similar Jobs

More Jobs at Exact Sciences

More Healthcare Jobs

Find similar Senior Cybersecurity Risk Management Analyst jobs: